Bosch kayıtları
bosch üreticisine ait 109 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 15
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-284 Improper Access Control9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-427 Uncontrolled Search Path Element7
- CWE-121 Stack-based Buffer Overflow6
- CWE-502 Deserialization of Untrusted Data5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
109 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2020-6779İstismar yok | Hard-coded Credentials in the Database of Bosch FSM-2500 Server and Bosch FSM-5000 Serverbosch · fsm-2500 firmware · CWE-798 | Kritik10,0 | — | %3,7 | 26 Oca 2021 |
40Planlayın | CVE-2020-6770İstismar yok | Deserialization of Untrusted Data in Bosch BVMS Mobile Video Servicebosch · bosch video management system mobile video service · CWE-502 | Kritik9,8 | — | %3,6 | 7 Şub 2020 |
40Planlayın | CVE-2018-19036İstismar yok | An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher.bosch · common product platform 4 firmware · CWE-119 | Kritik9,8 | — | %2,4 | 17 Ara 2018 |
40Planlayın | CVE-2022-32534İstismar yok | OS Command Injectionbosch · pra-es8p2s firmware · CWE-20 | Kritik9,8 | — | %2,4 | 23 Haz 2022 |
40Planlayın | CVE-2019-6957İstismar yok | Buffer Overflow for Bosch Video Systems, PSIM and Access Control Systemsbosch · access professional edition · CWE-787 | Kritik9,8 | — | %2,0 | 29 May 2019 |
40Planlayın | CVE-2018-20299İstismar yok | An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4.bosch · 360-indoor camera firmware · CWE-119 | Kritik9,8 | — | %1,9 | 19 Ara 2018 |
39İzleyin | CVE-2021-23857İstismar yok | Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passworbosch · rexroth indramotion mlc l20 firmware · CWE-836 | Kritik9,8 | — | %1,2 | 4 Eki 2021 |
39İzleyin | CVE-2019-11898İstismar yok | Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools.bosch · access · CWE-798 | Kritik9,9 | — | %1,1 | 12 Eyl 2019 |
39İzleyin | CVE-2019-11684İstismar yok | Improper Access Control in Bosch Video Recording Managerbosch · video recording manager · CWE-306 | Kritik9,8 | — | %1,0 | 26 Şub 2021 |
39İzleyin | CVE-2021-23853İstismar yok | Improper Input Validation of HTTP Headersbosch · cpp4 firmware · CWE-20 | Kritik9,8 | — | %0,9 | 9 Haz 2021 |
39İzleyin | CVE-2022-32535İstismar yok | Web server runs as rootbosch · pra-es8p2s firmware · CWE-250 | Kritik9,8 | — | %0,8 | 23 Haz 2022 |
39İzleyin | CVE-2023-48266İstismar yok | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exebosch · nexo-os · CWE-121 | Kritik9,8 | — | %0,8 | 10 Oca 2024 |
39İzleyin | CVE-2023-48264İstismar yok | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exebosch · nexo-os · CWE-121 | Kritik9,8 | — | %0,8 | 10 Oca 2024 |
39İzleyin | CVE-2023-48265İstismar yok | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exebosch · nexo-os · CWE-121 | Kritik9,8 | — | %0,8 | 10 Oca 2024 |
39İzleyin | CVE-2023-48263İstismar yok | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exebosch · nexo-os · CWE-122 | Kritik9,8 | — | %0,8 | 10 Oca 2024 |
39İzleyin | CVE-2023-48262İstismar yok | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exebosch · nexo-os · CWE-121 | Kritik9,8 | — | %0,8 | 10 Oca 2024 |
39İzleyin | CVE-2023-48245İstismar yok | The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) bosch · nexo-os · CWE-862 | Kritik9,8 | — | %0,6 | 10 Oca 2024 |
39İzleyin | CVE-2023-48250İstismar yok | The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded acbosch · nexo-os · CWE-798 | Kritik9,8 | — | %0,6 | 10 Oca 2024 |
39İzleyin | CVE-2023-48251İstismar yok | The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.bosch · nexo-os · CWE-798 | Kritik9,8 | — | %0,6 | 10 Oca 2024 |
37İzleyin | CVE-2020-6769İstismar yok | Missing Authentication for Critical Function in Bosch Video Streaming Gatewaybosch · video streaming gateway · CWE-306 | Kritik9,1 | — | %2,2 | 7 Şub 2020 |
36İzleyin | CVE-2019-6958İstismar yok | Improper Access Control for Bosch Video Systems, PSIM and Access Control Systemsbosch · access professional edition · CWE-306 | Kritik9,1 | — | %1,5 | 29 May 2019 |
36İzleyin | CVE-2021-23847İstismar yok | Unauthenticated Information Extraction Vulnerabilitybosch · cpp6 firmware · CWE-287 | Kritik9,1 | — | %1,4 | 9 Haz 2021 |
35İzleyin | CVE-2019-11897İstismar yok | Server-side request forgery in the backup & restore functionality of ProSyst mBS SDK and Bosch IoT Gateway Softwarebosch · iot gateway software · CWE-918 | Yüksek8,6 | — | %1,8 | 21 Ağu 2019 |
35İzleyin | CVE-2024-25002İstismar yok | Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.bosch · network synchronizer enterprise · CWE-78 | Yüksek8,8 | — | %1,2 | 25 Mar 2024 |
35İzleyin | CVE-2023-48243İstismar yok | The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS userbosch · nexo-os · CWE-22 | Yüksek8,8 | — | %1,1 | 10 Oca 2024 |
- CVE-2020-677941Planlayın
Hard-coded Credentials in the Database of Bosch FSM-2500 Server and Bosch FSM-5000 Server
KritikCVSS 10,0İstismar yokEPSS %4bosch · fsm-2500 firmware26 Oca 2021
- CVE-2020-677040Planlayın
Deserialization of Untrusted Data in Bosch BVMS Mobile Video Service
KritikCVSS 9,8İstismar yokEPSS %4bosch · bosch video management system mobile video service7 Şub 2020
- CVE-2018-1903640Planlayın
An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher.
KritikCVSS 9,8İstismar yokEPSS %2bosch · common product platform 4 firmware17 Ara 2018
- CVE-2022-3253440Planlayın
OS Command Injection
KritikCVSS 9,8İstismar yokEPSS %2bosch · pra-es8p2s firmware23 Haz 2022
- CVE-2019-695740Planlayın
Buffer Overflow for Bosch Video Systems, PSIM and Access Control Systems
KritikCVSS 9,8İstismar yokEPSS %2bosch · access professional edition29 May 2019
- CVE-2018-2029940Planlayın
An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4.
KritikCVSS 9,8İstismar yokEPSS %2bosch · 360-indoor camera firmware19 Ara 2018
- CVE-2021-2385739İzleyin
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passwor
KritikCVSS 9,8İstismar yokEPSS %1bosch · rexroth indramotion mlc l20 firmware4 Eki 2021
- CVE-2019-1189839İzleyin
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools.
KritikCVSS 9,9İstismar yokEPSS %1bosch · access12 Eyl 2019
- CVE-2019-1168439İzleyin
Improper Access Control in Bosch Video Recording Manager
KritikCVSS 9,8İstismar yokEPSS %1bosch · video recording manager26 Şub 2021
- CVE-2021-2385339İzleyin
Improper Input Validation of HTTP Headers
KritikCVSS 9,8İstismar yokEPSS %1bosch · cpp4 firmware9 Haz 2021
- CVE-2022-3253539İzleyin
Web server runs as root
KritikCVSS 9,8İstismar yokEPSS %1bosch · pra-es8p2s firmware23 Haz 2022
- CVE-2023-4826639İzleyin
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exe
KritikCVSS 9,8İstismar yokEPSS %1bosch · nexo-os10 Oca 2024
- CVE-2023-4826439İzleyin
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exe
KritikCVSS 9,8İstismar yokEPSS %1bosch · nexo-os10 Oca 2024
- CVE-2023-4826539İzleyin
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exe
KritikCVSS 9,8İstismar yokEPSS %1bosch · nexo-os10 Oca 2024
- CVE-2023-4826339İzleyin
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exe
KritikCVSS 9,8İstismar yokEPSS %1bosch · nexo-os10 Oca 2024
- CVE-2023-4826239İzleyin
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exe
KritikCVSS 9,8İstismar yokEPSS %1bosch · nexo-os10 Oca 2024
- CVE-2023-4824539İzleyin
The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”)
KritikCVSS 9,8İstismar yokEPSS %1bosch · nexo-os10 Oca 2024
- CVE-2023-4825039İzleyin
The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded ac
KritikCVSS 9,8İstismar yokEPSS %1bosch · nexo-os10 Oca 2024
- CVE-2023-4825139İzleyin
The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.
KritikCVSS 9,8İstismar yokEPSS %1bosch · nexo-os10 Oca 2024
- CVE-2020-676937İzleyin
Missing Authentication for Critical Function in Bosch Video Streaming Gateway
KritikCVSS 9,1İstismar yokEPSS %2bosch · video streaming gateway7 Şub 2020
- CVE-2019-695836İzleyin
Improper Access Control for Bosch Video Systems, PSIM and Access Control Systems
KritikCVSS 9,1İstismar yokEPSS %2bosch · access professional edition29 May 2019
- CVE-2021-2384736İzleyin
Unauthenticated Information Extraction Vulnerability
KritikCVSS 9,1İstismar yokEPSS %1bosch · cpp6 firmware9 Haz 2021
- CVE-2019-1189735İzleyin
Server-side request forgery in the backup & restore functionality of ProSyst mBS SDK and Bosch IoT Gateway Software
YüksekCVSS 8,6İstismar yokEPSS %2bosch · iot gateway software21 Ağu 2019
- CVE-2024-2500235İzleyin
Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.
YüksekCVSS 8,8İstismar yokEPSS %1bosch · network synchronizer enterprise25 Mar 2024
- CVE-2023-4824335İzleyin
The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user
YüksekCVSS 8,8İstismar yokEPSS %1bosch · nexo-os10 Oca 2024